Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jm66-cg57-jjv5 Azure Core is vulnerable to deserialization of untrusted data
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 21 Jan 2026 03:30:00 +0900

Type Values Removed Values Added
First Time appeared Microsoft azure Sdk For Python
CPEs cpe:2.3:a:microsoft:azure_sdk_for_python:*:*:*:*:*:*:*:*
Vendors & Products Microsoft azure Sdk For Python

Wed, 14 Jan 2026 04:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 Jan 2026 03:30:00 +0900

Type Values Removed Values Added
Description Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.
Title Azure Core shared client library for Python Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft azure Core Shared Client Library For Python
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:azure_core_shared_client_library_for_python:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Core Shared Client Library For Python
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-01-20T23:04:20.615Z

Reserved: 2025-12-11T21:02:05.732Z

Link: CVE-2026-21226

cve-icon Vulnrichment

Updated: 2026-01-13T18:28:29.233Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-13T19:16:23.987

Modified: 2026-01-20T18:23:54.057

Link: CVE-2026-21226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses